Skip to content

Commit d4360dc

Browse files
committed
Fix dependabot alert 31: upgrade logback to 1.5.25 (CVE-2026-1225)
1 parent ebf59a5 commit d4360dc

File tree

2 files changed

+14
-0
lines changed

2 files changed

+14
-0
lines changed

build.gradle

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -55,6 +55,17 @@ subprojects {
5555
}
5656
}
5757

58+
// Override logback version to fix CVE-2026-1225 (transitive via Spring Boot)
59+
configurations.all {
60+
resolutionStrategy.eachDependency {
61+
if (requested.group == 'ch.qos.logback') {
62+
useVersion libs.versions.logback.get()
63+
}
64+
}
65+
}
66+
67+
ext['logback.version'] = libs.versions.logback.get()
68+
5869
apply plugin: 'checkstyle'
5970
apply plugin: 'pmd'
6071

gradle/libs.versions.toml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
[versions]
22
java = "21"
33
spring-boot = "4.0.0"
4+
logback = "1.5.25" # Override Spring Boot managed version to fix CVE-2026-1225 (GHSA-qqpg-mvqg-649v)
45
spring-dependency-management = "1.1.7"
56
openapi-generator = "7.17.0"
67
openapi-tools = "0.2.8"
@@ -29,6 +30,8 @@ jakarta-validation-api = { group = "jakarta.validation", name = "jakarta.validat
2930
lombok = { group = "org.projectlombok", name = "lombok", version.ref = "lombok" }
3031
datadog-statsdclient = { group = "com.datadoghq", name = "java-dogstatsd-client", version.ref = "datadog-statsd" }
3132
commons-codec = { group = "commons-codec", name = "commons-codec", version.ref = "commons-codec" }
33+
logback-classic = { group = "ch.qos.logback", name = "logback-classic", version.ref = "logback" }
34+
logback-core = { group = "ch.qos.logback", name = "logback-core", version.ref = "logback" }
3235
find-bugs = { group = "com.google.code.findbugs", name = "jsr305", version.ref = "find-bugs" }
3336
# Testing
3437
mockito-core = { group = "org.mockito", name = "mockito-core", version.ref = "mockito" }

0 commit comments

Comments
 (0)